GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,968
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,616
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,040
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,050
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            1,623 advisories
        Filter by severity
        
      
      
    
                    
                      Shaman has soundness issues and is unmaintained
                    
                      
  Low
                    
                
                      
                        GHSA-7vjm-6qgq-3mrq
                      
                      was published
                        for
                        
                          shaman
                        
                        (Rust)
                      Nov 3, 2025 
                    
                  
                    
                      Anubis vulnerable to possible XSS via redir parameter when using subrequest auth mode
                    
                      
  Low
                    
                
                      
                        GHSA-cf57-c578-7jvv
                      
                      was published
                        for
                        
                          github.com/TecharoHQ/anubis
                        
                        (Go)
                      Oct 30, 2025 
                    
                  
                    
                      Byaidu PDFMathTranslate vulnerable to open redirect
                    
                      
  Low
                    
                
                      
                        CVE-2025-50736
                      
                      was published
                        for
                        
                          pdf2zh
                        
                        (pip)
                      Oct 30, 2025 
                    
                  
                    
                      Drupal Umami Analytics allows Cross-Site Scripting (XSS)
                    
                      
  Low
                    
                
                      
                        CVE-2025-10931
                      
                      was published
                        for
                        
                          drupal/umami_analytics
                        
                        (Composer)
                      Oct 30, 2025 
                    
                  
                    
                      Keycloak allows access to admin path through flaw
                    
                      
  Low
                    
                
                      
                        CVE-2025-10939
                      
                      was published
                        for
                        
                          org.keycloak:keycloak-quarkus-server
                        
                        (Maven)
                      Oct 28, 2025 
                    
                  
                    
                      Wasmtime vulnerable to segfault when using component resources
                    
                      
  Low
                    
                
                      
                        CVE-2025-62711
                      
                      was published
                        for
                        
                          wasmtime
                        
                        (Rust)
                      Oct 27, 2025 
                    
                  
                    
                      Apache Tomcat Vulnerable to Improper Neutralization of Escape, Meta, or Control Sequences
                    
                      
  Low
                    
                
                      
                        CVE-2025-55754
                      
                      was published
                        for
                        
                          org.apache.tomcat.embed:tomcat-embed-core
                        
                        (Maven)
                      Oct 27, 2025 
                    
                  
                    
                      Apache Tomcat Vulnerable to Improper Resource Shutdown or Release
                    
                      
  Low
                    
                
                      
                        CVE-2025-61795
                      
                      was published
                        for
                        
                          org.apache.tomcat.embed:tomcat-embed-core
                        
                        (Maven)
                      Oct 27, 2025 
                    
                  
                    
                      Liferay Portal Self Cross-site scripting (XSS) vulnerability on the edit Knowledge Base article page
                    
                      
  Low
                    
                
                      
                        CVE-2025-62255
                      
                      was published
                        for
                        
                          com.liferay:com.liferay.knowledge.base.web
                        
                        (Maven)
                      Oct 23, 2025 
                    
                  
                    
                      Liferay Portal and DXP are Missing Authorization in Collection Provider
                    
                      
  Low
                    
                
                      
                        CVE-2025-62247
                      
                      was published
                        for
                        
                          com.liferay:com.liferay.search.experiences.service
                        
                        (Maven)
                      Oct 22, 2025 
                    
                  
                    
                      Vert.x-Web vulnerable to Stored Cross-site Scripting in directory listings via file names
                    
                      
  Low
                    
                
                      
                        CVE-2025-11966
                      
                      was published
                        for
                        
                          io.vertx:vertx-web
                        
                        (Maven)
                      Oct 22, 2025 
                    
                  
                    
                      Borrowck Scarifices exposes uninitialized memory in any_as_u8_slice
                    
                      
  Low
                    
                
                      
                        GHSA-xcpm-76hf-c9cc
                      
                      was published
                        for
                        
                          borrowck_sacrifices
                        
                        (Rust)
                      Oct 22, 2025 
                    
                  
                    
                      Direct Ring Buffer has uninitialized memory exposure in create_ring_buffer
                    
                      
  Low
                    
                
                      
                        GHSA-fp5x-7m4q-449f
                      
                      was published
                        for
                        
                          direct_ring_buffer
                        
                        (Rust)
                      Oct 21, 2025 
                    
                  
                    
                      orx-pinned-vec has undefined behavior in index_of_ptr with empty slices
                    
                      
  Low
                    
                
                      
                        GHSA-h5j3-crg5-8jqm
                      
                      was published
                        for
                        
                          orx-pinned-vec
                        
                        (Rust)
                      Oct 21, 2025 
                    
                  
                    
                      uv has differential in tar extraction with PAX headers
                    
                      
  Low
                    
                
                      
                        GHSA-w476-p2h3-79g9
                      
                      was published
                        for
                        
                          uv
                        
                        (pip)
                      Oct 21, 2025 
                    
                  
                    
                      Shopware vulnerable to Server-Side Request Forgery (SSRF) – order invoice
                    
                      
  Low
                    
                
                      
                        GHSA-3cpp-fv95-mpr5
                      
                      was published
                        for
                        
                          shopware/core
                        
                        (Composer)
                      Oct 21, 2025 
                    
                  
                    
                      Shopware vulnerable to path traversal via Plugin upload
                    
                      
  Low
                    
                
                      
                        GHSA-6wh5-mw9h-5c3w
                      
                      was published
                        for
                        
                          shopware/core
                        
                        (Composer)
                      Oct 21, 2025 
                    
                  
                    
                      rollbar vulnerable to prototype pollution
                    
                      
  Low
                    
                
                      
                        CVE-2025-57325
                      
                      was published
                        for
                        
                          rollbar
                        
                        (npm)
                      Oct 20, 2025 
                    
                  
                    
                      TastyIgniter vulnerable to Cross-Site Scripting
                    
                      
  Low
                    
                
                      
                        CVE-2025-61417
                      
                      was published
                        for
                        
                          tastyigniter/tastyigniter
                        
                        (Composer)
                      Oct 20, 2025 
                    
                  
                    
                      Lobe Chat vulnerable to Server-Side Request Forgery with native web fetch module
                    
                      
  Low
                    
                
                      
                        CVE-2025-62505
                      
                      was published
                        for
                        
                          @lobehub/chat
                        
                        (npm)
                      Oct 17, 2025 
                    
                  
                    
                      LibreNMS alert-rules has a Cross-Site Scripting Vulnerability
                    
                      
  Low
                    
                
                      
                        CVE-2025-62412
                      
                      was published
                        for
                        
                          librenms/librenms
                        
                        (Composer)
                      Oct 16, 2025 
                    
                  
                    
                      PrestaShop Checkout Target PayPal merchant account hijacking from backoffice
                    
                      
  Low
                    
                
                      
                        CVE-2025-61924
                      
                      was published
                        for
                        
                          prestashop/ps_checkout
                        
                        (Composer)
                      Oct 16, 2025 
                    
                  
                    
                      Apache Traffic Control has an Inefficient Regular Expression Complexity vulnerability
                    
                      
  Low
                    
                
                      
                        CVE-2025-61581
                      
                      was published
                        for
                        
                          github.com/apache/trafficcontrol/v8
                        
                        (Go)
                      Oct 16, 2025 
                    
                  
                    
                      Mattermost has an Observable Timing Discrepancy vulnerability
                    
                      
  Low
                    
                
                      
                        CVE-2025-54499
                      
                      was published
                        for
                        
                          github.com/mattermost/mattermost-server
                        
                        (Go)
                      Oct 16, 2025 
                    
                  
                    
                      Mattermost has an Incorrect Authorization vulnerability
                    
                      
  Low
                    
                
                      
                        CVE-2025-10545
                      
                      was published
                        for
                        
                          github.com/mattermost/mattermost-server
                        
                        (Go)
                      Oct 16, 2025 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API